PT-2019-13399 · Medtronic · Medtronic Valleylab Ft10 Energy Platform+1

Published

2019-11-08

·

Updated

2020-10-09

·

CVE-2019-13535

CVSS v3.1

4.6

Medium

VectorAV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Medtronic Valleylab FT10 Energy Platform versions 2.1.0 and lower Medtronic Valleylab FT10 Energy Platform version 2.0.3 and lower Valleylab LS10 Energy Platform versions 1.20.2 and lower
Description The issue concerns the RFID security mechanism, which fails to apply read protection. This allows for full read access of the RFID security mechanism data.
Recommendations For Medtronic Valleylab FT10 Energy Platform versions 2.1.0 and lower, consider restricting access to the RFID security mechanism until a fix is available. For Medtronic Valleylab FT10 Energy Platform version 2.0.3 and lower, restrict access to the RFID security mechanism until a fix is available. For Valleylab LS10 Energy Platform versions 1.20.2 and lower, restrict access to the RFID security mechanism until a fix is available.

Fix

Incorrect Permission

Protection Mechanism Failure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-13535

Affected Products

Medtronic Valleylab Ft10 Energy Platform
Valleylab Ft10 Energy Platform